Security Compliance
All email alerts have stopped and SEM rules have stopped firing
All rules have stopped firing in Security Event Manager.
First published date
Last published date
Overview
Product section
Cause
Resolution
The SEM system date or time may not be accurate
- Connect to SEM via SSH/Putty on port 32022 with the cmc account.
- Type appliance, press Enter, type dateconfig, and press Enter four times.
- Verify the displayed date, time, and time zone are accurate down to the minute.
- If the time is NOT accurate, run dateconfig again and provide the correct date and time. If you need to correct the time zone, run tzconfig.
Configure an NTP Server (Recommended)
You may want to configure SEM to use one or more NTP servers to keep accurate time going forward. You need to configure your virtual appliance to not sync its time with the VM host.
-
In VMware vCenter, highlight your appliance and go to Edit Settings > Options > VMware Tools and clear the Synchronize guest time with host check box.
-
In Hyper-V, highlight your appliance, and then go to Settings... > Integration Services and clear the Time synchronization check box.
- Still in the appliance menu, type ntpconfig and press Enter twice.
- Enter the hostname or IP address of your NTP server. You can also specify an internet server, such as 0.north-america.pool.ntp.org
- Type y to confirm your server and press Enter. Type y if you want to specify another server or n if you don't and press Enter.
- It will state Running ntpdate to synchronize clock and return you to the prompt. You should now be time synced with NTP.
SEM has performance issues
If SEM is under excessive load because hardware reservations are not configured or insufficient for your event load, rules may stop firing entirely. Refer to the Planning your deployment section of SEM Getting Started Guide to determine if you have adequate reservations for your environment.
Your account or your email address was removed
- On the SEM toolbar, navigate to Build > Users and verify that your account is present and has the correct email address assigned to it.
- Edit a rule you are expecting to fire and verify your account is checked under the Users drop-down below Send Email Message.
The SEM email connector stopped and is experiencing a performance issue
- This issue could also be caused by having the email connector disabled under Manage > Appliances in the SEM web (or Air) console, combined with a performance or timing issue.
- Check the connectors enabled in SEM in the Manage > Appliances section of your web (or Air) console by clicking the gear icon to the left of your problematic SEM Appliance, and then selecting Connectors from the drop-down list.
- Once you select the Connectors option from the drop-down list, a window appears that has all available connectors listed. Check the box on the left side of that window to see only the configured connectors.
- Scroll down until you see the email connector, and then check to see if it is started or stopped.
- If the email connector is not started, click the gear icon to the left of the connector, and then select Start.
- Continue to troubleshoot any performance or timing issues.